Exabeam Agentic SOC brings AI investigations on-premises
Exabeam has released a set of new capabilities for what it calls the Agentic SOC, extending AI-driven investigation, execution and governance to both cloud and on-premises deployments. The release also includes a modernized LogRhythm SIEM platform for organizations that keep security data inside their own environment. A SIEM (security information and event management) system collects and analyzes logs from across an organization's network.
The company's argument is that analyst workflows alone can no longer keep up with machine-speed threats. Enterprises are also running more goal-driven AI agents and autonomous workflows, and these need to be monitored as well.
Exabeam has applied machine learning to security operations for more than ten years. That work started with user and entity behavior analytics (UEBA), which spots unusual activity by comparing it with normal patterns for users and devices. Over the past two years, the company added Exabeam Nova AI, the Exabeam MCP Server and Agent Behavior Analytics (ABA). ABA watches AI agents alongside human users.
"The next generation of the SOC won't be defined by more alerts or more automation. It will be defined by how effectively people and AI agents work together," said Steve Wilson, Chief AI and Product Officer at Exabeam.
Nova AI becomes a persistent investigator
Nova AI now works across the entire platform. As incidents develop, it gathers context, runs secondary searches and pulls entity profiles. Exabeam says its own security operations team measured Nova AI triaging an average case in about 10 minutes. A human analyst would typically need around five hours, so the AI was 30 times faster by the company's count. A new Related Cases feature automatically groups connected incidents, so analysts see the wider picture right away.
The company also launched the Exabeam Agentic SOC Plugin for Anthropic Claude Code and OpenAI Codex. It brings guided workflows into these AI command-line tools, so analysts can triage alerts, prioritize cases and investigate using natural-language commands. Exabeam describes it as the first in a planned series of skills from its Agent Skills Marketplace.
A deeper Claude Enterprise integration puts prompts, tool calls and actions into a single timeline. It then applies event-time analysis and behavior-based correlation to detect rogue agents and behavioral drift.
For management reporting, Executive Digest produces boardroom-ready security metrics. Outcomes Navigator Overrides lets teams adjust risk scoring and keep compliance metrics separate across business units.
Eduardo Sulvaran Velazquez, Subdirector Cyber Risk Management at E-Global, said Nova AI has helped his team prioritize cases more effectively. He added that AI can "materially improve the speed and efficiency of security investigations without removing human judgment from the process."
LogRhythm brings agentic features on-premises
For organizations that keep infrastructure, data or AI workloads on-premises, the updated LogRhythm SIEM Platform runs AI-assisted security operations locally.
New generative AI collectors for ChatGPT, Google Gemini and GitHub Copilot feed enterprise AI activity into LogRhythm Intelligence Analytics, giving teams a central view of how these tools are used. A new community Model Context Protocol (MCP) server lets teams query, investigate and triage security data with local generative AI models, without the data leaving their environment. MCP is a standard way of connecting AI models to external tools and data sources.
The platform now runs on OpenSearch after an in-place migration from Elasticsearch. Exabeam says this improves speed and scale. It also supports a new self-service reporting engine with AI governance and audit-ready compliance reporting.
"The evolution toward an agentic SOC is less about removing analysts from the process and more about changing where their time and judgment are applied," said Michelle Abraham, Research Vice President, Security and Trust, at IDC.
Our Take
Two themes stand out in this release. The first is speed. The 30x triage figure comes from Exabeam's own team rather than independent testing, so readers should treat it as a vendor claim. Still, it reflects a wider push to automate the early stages of investigations. That push is already reshaping SOC staffing, and recent research suggests entry-level analyst roles are getting harder to land.
The second theme is visibility into AI agents themselves. Exabeam's Claude Enterprise integration and the generative AI collectors follow a similar move by Anthropic, whose Compliance API sends chat data to security tools. This suggests agent monitoring is becoming a standard SOC task. With signs that attackers are ahead in the AI race, it is worth watching whether rogue-agent detection holds up in real environments, and whether the on-premises option appeals to regulated sectors that cannot send logs to the cloud.
